gangsta virus..

Discussion in 'Malware Help (A Specialist Will Reply)' started by lenny spero, Apr 9, 2009.

  1. lenny spero

    lenny spero Private E-2

    i have a virus so bad that it should be locked up in sing-sing for the rest of its life..
    i ran a bunch of anti-virus's and it cleaned alot of crap out.
    here are the symptoms i cant acess alot of the administrative stuff...when i first got the virus it had a weird backround message..infected with ad-ware etc..
    i downloaded that pirform ccleaner and ran it and took a bunch of crap off.
    i dont have any of the discs from the computer so none of that stuff is an option

    thanks in advance for the help...:)
     
  2. lenny spero

    lenny spero Private E-2

    i ran all the scans in the read me first that my computer would let me..
    this thing is driveing me nuts!!
    any help would be greatly apreciated
     
  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there and welcome, if you have done what you said above then the next part of the process is attaching the 4 requested logs. Without those, we cannnot assist you in malware removal.

    Please get me logs from the below:

    • SUPERantispyware
    • Malware Bytes
    • Combofix <--- C:\Combofix.txt
    • MgTools <--- C:\Mglogs.zip

    Thanks
    Kes
     
  4. lenny spero

    lenny spero Private E-2

    here is the report from the malware bites my computer wont let me download the super spyware..well i can download it but i cant run it..THANKS FOR THE HELP!!!
    im unsure how to use the winRAR but i have it on my desktop..
    when i run the combofix the following error message shows up.
    C:\windows\regedit.exe is missing copy from another machine.... ???


    EDIT NOTE: Please do not post inline logs. Use the manage attachments button.
     

    Attached Files:

    Last edited by a moderator: Apr 14, 2009
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Attach the C:\mglogs.zip and another MBAM log showing you fixed what it found as for some I see that you took no action for.

    Thanks
    Kes
     
  6. lenny spero

    lenny spero Private E-2

    MGlogs.zip - ZIP archive, unpacked size 398,416 bytes
    i hope that works..ill look into that other log now
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  8. lenny spero

    lenny spero Private E-2

    here is the most recent log i think.
    im not too computer savy so thanks alot for the help.
     

    Attached Files:

  9. lenny spero

    lenny spero Private E-2

    with the winRAR am im unsure how to use this am i supposed to use the "Scan for Rootkits"...thanks again.
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What are you referring to? All you were asked to do is to attach the C:\MGLogs.zip.
     
  11. lenny spero

    lenny spero Private E-2

    i hope this is correct..
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are missing the HJT log and your Runkeys log is empty. Did you get any error messeges when you ran the MGTools.exe? You must make the agreement to the HJT license when you run the program and let to run until it tells you to hit any key.

    Let's have you try it again:
    run the C:\MGtools\GetLogs.bat file by double clicking on it, let it run to completion. Then attach the new C:\MGlogs.zip file
     
  13. lenny spero

    lenny spero Private E-2

    ok i ran it to the end..here is the new zip..thanks again. im not the best with computers.
     

    Attached Files:

  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    OK....let's try this tact....Please attach the logs from running SAS and Combo.
    You can copy regedit form another machine as long as it is the same version.
    What happens when you run SAS?
     
    Last edited: Apr 14, 2009
  15. lenny spero

    lenny spero Private E-2

    tim when i try to run SAS i get an error message that says something like "the administrator has blocked this application" or something similar. and whan i try to run the combo fix this error message appears,,
    c\windows\regedit.exe is missing copy obe from another machine.
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Have you tried running either of them in safe mode? Did you try renaming them?

    Go to run / type "sfc /scannow" without qoutes and have your xp cd handly. Run it at least twice.
     
  17. lenny spero

    lenny spero Private E-2

    ive been running im safe mode for almost every scan.i have even more limited use in regular mode. i dont have any of the cd's for this computer. it was given to me by a friend..ill try to re-name the files and run them
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you get this computer with the current problems? Do you know someone you can borrow their cd from? Must be either the Pro or Home version depending on what you have installed.

    When you run the MGTools, you don't get a pop up for HJT?
     
  19. lenny spero

    lenny spero Private E-2

    the computer worked fine when i got it ive had it for about 2 years,,
    mabe i could just buy a new windows xp cd?..
    i ran the HJT ill attach the log.
    the computer seems to work fine except i dont have control over the admin options and i cant download anything in regular mode and even in safe mode some things i can DL
     

    Attached Files:

  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    I am not seeing any malware..so let's see what this turns up:
    Using BitDefender Online Scan

    Using BitDefender Online Scan.
     
  21. lenny spero

    lenny spero Private E-2

    i copy and pasted the info to my notebook and saved it as fixME.reg when i go to open it it ask's me what program i want to open it with?..
    im also running the bit defender now....thanks for the help,,
     
  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
     
  23. lenny spero

    lenny spero Private E-2

    thats what i did...the bitdefender has grabbed a bunch of virus's when the scan is over ill post a log so you can see which ones they were..
     
  24. lenny spero

    lenny spero Private E-2

    here is the log from the bd scan it found and removed a few things it seems..
    BitDefender Online Scanner - Real Time Virus Report

    generated at: Wed, Apr 15, 2009 - 18:28:31

    --------------------------------------------------------------------------------



    Scan Info


    Scanned Files
    221352

    Infected Files
    5



    irus Detected



    Trojan.Generic.1457504
    2

    Spyware.945
    3
     
  25. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The directions said to save the log as a txt file (text) and attach it. This tells me only that it found some things, not what it found.
     
  26. lenny spero

    lenny spero Private E-2

    here is the file saved as a txt file..thanks again
     

    Attached Files:

  27. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What malware problems are you currently having?
     
  28. lenny spero

    lenny spero Private E-2

    i cannot access admin options in safe mode or regular mode.
    i can not download really anything..i cant print anything..my volume control is disabled..basically alot of my admin options are being controled by something
    i cant do a system restore
    i cant change my backround.
     
  29. lenny spero

    lenny spero Private E-2

    im in regular startup mode now and i cant download anything..i tried to do some online virus scans and i cant do that either
    can i download something in safe mode burn it to a disc and then try it in regular mode?..
    also i went into my windows/32 file and there is all kind of stuff i dont recognize in there should i delete that stuff?
     
  30. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am beginning to wonder if this is not a system problem instead of a malware problem.

    Let's try doing this:
    Download Dr.Web CureIt and save it to your desktop.

    • Doubleclick the cureit-beta.exe file and allow to run
    • If it prompts you about getting any updates, get the update and then rerun the cureit-beta.exe installation.
    • When it finishes you will have a green window with a Start and and Update selection. Click Start
    • the Express Scan of your PC window will come up. Click OK to scan main memory to detect infected process in memory.
    • If anything is found in memory, click the yes button when it asks you if you want to cure it. This is only a short scan.
    • You may see a popup window to Buy or get a discount on the program. Just click the X at the top right to close this popup. The scan will continue.
    • Once the short scan is completed, click the Custom Scan radio button. Then Select each of your hard disk drives (that is if you have more than one). A red dot shows which drives have been chosen.
    • Click the green arrow at the right under the Dr.Web logo, and the scan will start.
    • Click 'Yes to all' if it finds any problems and asks if you want to cure or move the file.
    • When the scan has finished, look if you can click next icon next to the files found:
      http://users.telenet.be/bluepatchy/miekiemoes/images/check.gif
    • If so, click it and then click the next icon right below and select Move incurable as you'll see in next image:
      http://users.telenet.be/bluepatchy/miekiemoes/images/move.gif
    • This will move it to the %userprofile%\DoctorWeb\quarantaine-folder if it can't be cured. (this in case if we need samples)
    • After selecting, in the Dr.Web CureIt menu on top, click file and choose save report list
    • Save the report to your desktop. The report will be called DrWeb.csv
    • Close Dr.Web Cureit.
    • Reboot your computer!! This is necessary because there could be files in use that will be moved or deleted during reboot.
    • After reboot, rename the DrWeb.csv file to DrWeb.txt so that it can be uploaded here and then attach the log from Dr.Web to your next reply
     
  31. lenny spero

    lenny spero Private E-2

    ah that got a bunch of stuff....here is the report ..
    like you said it couldnt remove it but it moved it to that quarintine folder here is the log....thanks again..thats a wicked program


    heres tha log..
     

    Attached Files:

  32. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good, now please re-run both SAS and MBAM, then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * SAS
    * MBAM
    * C:\MGlogs.zip
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds